Like what you hear? Tweet it using:...

30
Like what you hear? Tweet it using: #Sec360

Transcript of Like what you hear? Tweet it using:...

Page 1: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

Like what you hear? Tweet it using: #Sec360

Page 2: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

How Do You Spell CISO?

Secure360

Wed. May 14, 2014

[email protected]

[email protected] @bcaplin

http://about.me/barrycaplin

http://securityandcoffee.blogspot.com

Barry Caplin

Chief Information Security Official

Fairview Health Services

Page 3: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

http://about.me/barrycaplin

securityandcoffee.blogspot.com

@bcaplin

Page 4: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

NO BANNER + logo

Fairview Overview

• Not-for-profit established in 1906

• Academic Health System since 1997 partnership with University of Minnesota

• >22K employees

• >3,300 aligned physicians

Employed, faculty, independent

• 7 hospitals/medical centers (>2,500 staffed beds)

• 40-plus primary care clinics

• 55-plus specialty clinics

• 47 senior housing locations

• 30-plus retail pharmacies

4

2012 data

•5.7 million outpatient encounters

•74,649 inpatient admissions

•$2.8 billion total assets

•$3.2 billion total revenue

Page 5: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

Who is Fairview?

A partnership of North Memorial and Fairview

Page 6: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

Did you ever think about…

Page 7: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

Challenges

• Keep it simple

• Keep it High Level

• Don’t let ‘em pull you in to the weeds

Page 8: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

Game Time!

Page 9: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

First Quarter

• Learn the Business

• Culture of Security

• Baseline the Organization

Page 10: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

Learn the Business

Business/Ops lead – not Security or IT

• Do you know?

Industry

Niche

Mission/Vision

Why/What/How

The Organization

Page 11: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

Learn the Business

• Ask Questions

• Org Charts

• Get Out of the Building!

• 1:1’s; Divisional meetings;

Leaders; C-suite

Page 12: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

Learn the Business

• Agenda

Introduction

learn about the business area,

what works and what doesn't,

partnership opportunities,

what can I do for you?

• Establish your office; Create Champions

Page 13: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

A Culture of Security

A journey of a thousand miles begins with a single step.

- Lao-tzu, The Way of Lao-tzu Chinese philosopher (604 BC - 531 BC)

You gotta start somewhere. - Me

Page 14: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

A Culture of Security

• Is there existing training?

• Train for Compliance

• Awareness to reinforce

• Create Evangelists

Page 15: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

A Culture of Security

• Be Relevant

• Connect to the Business

• Seek out and Destroy controls that add no value

Page 16: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

Baseline the Organization

Helps you:

• Know where things stand

• Show progress

Page 17: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

Baseline the Organization

Methods:

• Compare against known standard

• Maturity Model

CObIT Security Baseline

CObIT Maturity Assessment Tool

Gartner IT Score

Homegrown

Page 18: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

In your spare time…

• Low hanging fruit

• Other duties as assigned

Page 19: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

Second Quarter

• Strategic Planning

• Tactical Planning

• Roadmap

Page 20: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

SECTION

Security is not a Project…. It’s a Lifestyle!

20

Page 21: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

Strategic Planning

Page 22: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

Strategic Planning

• High-level

• Outcomes

• Framework

NIST

CObIT

HITRUST

ISO27001

Page 23: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

Strategic Planning

• Business info +

• Baseline analysis +

• Risk Assessment +

Threat Assessment

Assets; Actors; Actions

• Vision =

Time Travel

Page 24: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

Threat Modeling/Assessment

• Elevation of Privilege http://www.microsoft.com/security/sdl/adopt/eop.aspx

• Cntl-Alt-Hack http://www.controlalthack.com/

• UW Security Cards http://securitycards.cs.washington.edu/

Page 25: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

Tactical Planning

• Tactics are “How?”

Support each strategy

More granular

Shorter timeframe (1-3 yrs.)

Page 26: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

Strategy/Tactics

Improve Situational Awareness

Improve Access Management

capability

Build a Vulnerability Management

program

Detect malicious software, block

disallowed software, allow approved

software and detect unauthorized changes

Page 27: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

Roadmap

Page 28: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

Third Quarter…

• Execute!

• Metrics/KPIs/KRIs

• Communicating Risk

• BoD Reports

• Security Organization

Page 29: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established

…And Beyond

The “game” never ends.

• Iterative processes

• Support the “bridges”

• Living documents

• Review and refine

Page 30: Like what you hear? Tweet it using: #Sec360secure360.org/wp-content/uploads/2014/06/The-CISO-Guide... · 2016-09-21 · NO BANNER + logo Fairview Overview • Not-for-profit established